A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3849 | Issue Tracking Patch Third Party Advisory |
https://moodle.org/mod/forum/discuss.php?d=384012#p1547744 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2019-03-26 18:29
Updated : 2020-10-16 18:48
NVD link : CVE-2019-3849
Mitre link : CVE-2019-3849
CVE.ORG link : CVE-2019-3849
JSON object : View
Products Affected
moodle
- moodle